A security flaw has been identified in Apache HTTP Server, a widely used web server platform. The issue exists in its mod_proxy feature, which routes incoming visitor requests to the backend server that hosts your website’s content.
A specially crafted request can exploit this vulnerability to trick the proxy into sending the request to a server chosen by the attacker, rather than your intended backend server. This flaw affects all versions of Apache HTTP Server 2.4.48 and earlier.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438